Aggregator
Please support the site operations by clicking ads.
CVE-2026-81754 | fernandot Vigilant Plugin up to 2.10.2 on WordPress cross site scripting
CVE-2026-7438 | boldthemes Bold Timeline Lite Plugin up to 1.2.8 on WordPress Shortcode bold_timeline_item supertitle/subtitle cross site scripting
CVE-2026-18964 | Premio Floating Chat Widget Contact Chat Icons Telegram Chat Line Messenger WeChat Email SMS Call Button Plugin cross site scripting
FDE 会是网安行业的 “诺亚方舟” 吗?
CVE-2026-18579 | opajaap WP Photo Album Plus Plugin up to 9.2.08.003 on WordPress wp_ajax_nopriv_wppa Endpoint getshortcodedrenderedfenodelay HTTP_X_FORWARDED_FOR cross site scripting
CVE-2026-81825 | specialk Simple Ajax Chat Plugin up to 20260811 on WordPress cross site scripting
CVE-2026-78172 | themifyme Themify Plugin up to 1.5.5 on WordPress cross site scripting
CVE-2026-77150 | UniteCMS Unlimited Elements for Elementor Plugin up to 2.0.16 on WordPress show_preview data[name] cross site scripting
CVE-2026-18562 | realmag777 HUSKY – Products Filter Professional for WooCommerce Plugin wp_load_js cross site scripting
CVE-2026-19991 | UsersWP Plugin up to 1.2.70 on WordPress AJAX upload_file_remove File path traversal
Ubuntu 24.04.5 LTS release patches security bugs across ten flavors
Canonical shipped Ubuntu 24.04.5 LTS, bundling security updates and fixes for high-severity bugs into new installation media for the “Noble Numbat” release. Anyone installing fresh now gets those corrections baked in from the start, cutting the batch of updates that would normally follow setup. The point release covers more than the desktop and server editions. Nine other flavors, including Kubuntu, Xubuntu, Ubuntu MATE, Ubuntu Studio, and Edubuntu, also moved to version 24.04.5, each carrying its … More →
The post Ubuntu 24.04.5 LTS release patches security bugs across ten flavors appeared first on Help Net Security.
CVE-2026-15462 | gingerplugins Sticky Chat Widget Plugin up to 1.4.2 on WordPress save_form_data scw_form_fields sql injection
CVE-2026-11446 | Booktics Plugin up to 1.0.23 on WordPress Permission Callback orders create_order_permission privileges management
CVE-2026-18561 | UniteCMS Unlimited Elements for Elementor Plugin up to 2.0.16 on WordPress getWhereString addontype sql injection
CVE-2026-8778 | mulika MIPL Grouped Checkout Fields for WooCommerce Plugin mipl_wc_upload_file unrestricted upload
CVE-2026-19985 | comesio Relevanssi Plugin up to 4.28.1 on WordPress Debug lib/debug.php relevanssi_debug_array s/post_types/orderby cross site scripting
CVE-2026-12215 | xootix OTP Login & Register Woocommerce Plugin up to 2.7.2 on WordPress OTP Rate Limit login_user_with_otp ip_address excessive authentication
New infosec products of the week: September 11, 2026
Here’s a look at the most interesting products from the past week, featuring releases from Akeyless, Orchid Security, Scytale, and Securin. Securin Platform helps security teams prove when attack paths are closed Securin has announced the general availability of the Securin Platform, an AI-native Preemptive Exposure Management platform designed to answer three questions security teams struggle with every day: What can attackers actually exploit? What should we fix first? And did the fix actually work? … More →
The post New infosec products of the week: September 11, 2026 appeared first on Help Net Security.